Impact
The vulnerability is an unauthenticated PHP Object Injection in ThemeREX Addons plugin versions older than 2.45.0. When an attacker supplies a specially crafted serialized payload that the plugin unserializes, arbitrary PHP code can be executed on the host, enabling a full compromise of the WordPress installation. Based on the description, it is inferred that the attacker could run any code on the server, potentially affecting confidentiality, integrity, and availability of the site.
Affected Systems
The Vulnerability impacts the ThemeREX ThemeREX Addons WordPress plugin. Any installation running a version prior to 2.45.0 is affected. ThemeREX distributes the plugin under the ThemeRex vendor name and the affected versions are all releases before the 2.45.0 update.
Risk and Exploitability
The CVSS score of 9.8 indicates Critical severity, and the EPSS score of less than 1% suggests that exploitation is currently rare. The flaw is unauthenticated, meaning it can be triggered without logging into the site. Based on the description, the likely attack vector is delivery of a crafted serialized payload through a publicly accessible HTTP request that triggers the plugin’s unserialize routine. The vulnerability is not listed in CISA KEV, and no public exploit evidence is available at the time of this analysis.
OpenCVE Enrichment